scrapfly-browser
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill’s core purpose and official Scrapfly data flow are coherent, but the optional BYOP connector materially expands risk. It instructs users to curl|sh a same-org but unverifiable binary and pass API-linked credentials through it, which triggers a high security-risk classification even without clear malicious intent.
Confidence: 90%Severity: 82%
Audit Metadata